A fork of a project that does security patches only is an interesting idea...
Since then a diff of the two projects will be a perfect list of security issues and will make designing an attack rather easy...
Only until the next feature lands in upstream, likely accompanied by some refactoring.
Only until the next feature lands in upstream, likely accompanied by some refactoring.